LIVE DATA

Recent Data Breaches

1,032+ known breaches tracked. See if your accounts are affected.

1,032

Total Breaches

17.8B

Accounts Compromised

Aug 15, 2026

Most Recent Breach

990

Verified Breaches

Showing 20 of 1032 breaches

Oz Hair and Beauty

ozhairandbeauty.com
Verified
Aug 15, 20262M accounts
Email addressesGeographic locationsNamesPhone numbersPurchases

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.

Check if you're affected

Carhartt

carhartt.com
Verified
Aug 13, 202612.9M accounts
Email addressesNamesPhone numbersPhysical addresses

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.

Check if you're affected
Verified
Aug 6, 2026144.5K accounts
Email addressesNamesPasswordsUsernames

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

Check if you're affected
Verified
Aug 1, 2026218.4K accounts
Email addressesNamesPhone numbersPhysical addresses

In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.

Check if you're affected

RingCentral

ringcentral.com
Verified
Jul 27, 20261.6M accounts
Email addressesNamesPhone numbersPhysical addresses

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

Check if you're affected

SplitVPN

splitvpn.io
Verified
Jul 21, 2026865.3K accounts
Device informationEmail addressesGeographic locationsIP addressesPartial credit card data

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

Check if you're affected

Exact Sciences

exactsciences.com
Verified
Jul 15, 202610.9M accounts
Dates of birthEmail addressesGendersNamesPersonal health dataPhone numbers+1 more

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

Check if you're affected

Brinks Home

brinkshome.com
Verified
Jul 13, 2026732.2K accounts
Dates of birthEmail addressesNamesPartial credit card dataPhone numbersPhysical addresses+1 more

In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".

Check if you're affected
Verified
Jul 1, 2026821.1K accounts
Email addressesEmployersJob titlesNamesPhysical addressesSupport tickets

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.

Check if you're affected

Inter-Con Security

icsecurity.com
Verified
Jun 18, 2026276.1K accounts
Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.

Check if you're affected

Operation Endgame 4.0

Verified
Jun 18, 20264.3M accounts
Email addressesPasswords

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.

Check if you're affected

Houston City College

hccs.edu
Verified
Jun 16, 2026831.6K accounts
Academic recordsCitizenship statusesDates of birthEmail addressesGendersNames+2 more

In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.

Check if you're affected

Glendale Community College

glendale.edu
Verified
Jun 15, 2026793.9K accounts
Academic recordsDates of birthEmail addressesGendersGovernment issued IDsNames+2 more

In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".

Check if you're affected

June 2026 Stealer Logs

Verified
Jun 15, 202656.3M accounts
Email addressesPasswords

In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.

Check if you're affected

Moody Bible Institute

moody.edu
Verified
Jun 15, 20262.3M accounts
Dates of birthEmail addressesGendersMarital statusesNamesPhone numbers+1 more

In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".

Check if you're affected
Verified
Jun 15, 20262.7M accounts
Customer feedbackEmail addressesEmployersJob titlesNamesPhone numbers+2 more

In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.

Check if you're affected

American Tower

americantower.com
Verified
Jun 12, 2026216.6K accounts
Email addressesJob titlesNamesPhone numbersPhysical addresses

In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.

Check if you're affected

JCPenney

jcpenny.com
Verified
Jun 12, 2026368.4K accounts
Dates of birthEmail addressesGovernment issued IDsJob titlesNamesPhone numbers+2 more

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.

Check if you're affected

Ralph Lauren

ralphlauren.com
Verified
Jun 11, 2026139.9K accounts
Age groupsEmail addressesGendersNamesPhone numbers

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

Check if you're affected

Goose Creek

goosecreek.com
Verified
Jun 9, 20266.6M accounts
Email addressesNamesPhone numbersPhysical addressesPurchases

In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.

Check if you're affected

Think you're affected?

Check your email against 1,032 known breaches instantly. Find out what data has been exposed.

Check Your Email Now